CVE Database
/

CVE-2021-47740

Back to search

CVE-2021-47740

Published: Dec 31, 2025

Modified: Jan 2, 2026

PUBLISHED

CVSS v3.1

7.5

HIGH

Description

KZTech JT3500V 4G LTE CPE 2.0.1 contains a session management vulnerability that allows attackers to reuse old session credentials without proper expiration. Attackers can exploit the weak session handling to maintain unauthorized access and potentially compromise device authentication mechanisms.

VendorProductVersions

KZ Broadband Technologies, Ltd.

JT3500V

affected
2.0.1B1064
affected
2.0.1B1047

KZ Broadband Technologies, Ltd.

AM6200M

affected
2.0.0B3210

KZ Broadband Technologies, Ltd.

AM6000N

affected
2.0.0B3042

KZ Broadband Technologies, Ltd.

AM5000W

affected
2.0.0B3037

KZ Broadband Technologies, Ltd.

AM4200M

affected
2.0.0B2996

KZ Broadband Technologies, Ltd.

AM4100V

affected
2.0.0B2988

KZ Broadband Technologies, Ltd.

AM3500MW

affected
2.0.0B1092

KZ Broadband Technologies, Ltd.

AM3410V

affected
2.0.0B1085

KZ Broadband Technologies, Ltd.

AM3300V

affected
2.0.0B1060

KZ Broadband Technologies, Ltd.

AM3100E

affected
2.0.0B981

KZ Broadband Technologies, Ltd.

AM3100V

affected
2.0.0B946

KZ Broadband Technologies, Ltd.

AM3000M

affected
2.0.0B21

KZ Broadband Technologies, Ltd.

KZ7621U

affected
2.0.0B14

KZ Broadband Technologies, Ltd.

KZ3220M

affected
2.0.0B04

KZ Broadband Technologies, Ltd.

KZ3120R

affected
2.0.0B01

Weaknesses (CWE)

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Attack Vector

Network

Attack Complexity

Low

Privileges Required

None

User Interaction

None

Scope

Unchanged

Confidentiality

High

Integrity

None

Availability

None

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now